ABSTRACT OF THE DISCLOSURE 

In order to provide an information security policy 
evaluation system in which information security policies can be 
efficiently and appropriately defined and operated in an 
5 organization, such as a corporation/ treated threats operated 
on a second site 102 are transmitted from a second information 
processing apparatus 112 on the second site 102 to a first 
information processing apparatus 111 on a first site 101, threat 
information is transmitted from a third site 103 collecting 

10 information on threats to the first information processing 
apparatus 111 on the first site 101- The first information 
processing apparatus 111 extracts treated threats which have been 
effective for threats having occurred actually, and untreated 
threats, out of the received treated threat and generates an 

15 evaluation report in which these are described. Moreover, a 
compensation amount of insurance against threats is changed based 
on the generated evaluation report. 
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